CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-25T02:51:56Z•d4ebcb648cea7353d4662182318f9d06b74eda01897115ad5acfc263eb749f72
CISADDoS-for-hireFBI advisoryKEVKali365KimWolfKnown Exploited VulnerabilitiesMeta settlementMicrosoft 365OAuth token theftSupreme Courtbotnetcybercrimegeofence searchesphishing-as-a-serviceprivacystudent mental healthvulnerability disclosurevulnerability reporting
What happened
A set of security news items: CISA launched a nomination form to let researchers, vendors and partners submit bugs for inclusion in its Known Exploited Vulnerabilities (KEV) catalog. The FBI issued an advisory on Kali365, a Telegram-based phishing‑as‑a‑service that harvests OAuth tokens to compromise Microsoft 365 tenants. Separately, Meta settled a school‑district lawsuit over alleged addictive design harms to students. The Supreme Court’s pending Chatrie decision could reshape U.S. privacy law around geofence searches. U.S. authorities also charged a Canadian operator of the KimWolf DDoS bot
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- d4ebcb648cea7353d4662182318f9d06b74eda01897115ad5acfc263eb749f72
- Enrichment time
- 2026-05-25T02:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.